Contributed by jose on from the keeping-track-of-things dept.
does anyone know/use a configurable network traffic analyzer? We have an 1000+ network in our dorm, gigabit connenction to the university, and we'd like to monitor and filter the traffic of our users (all of them have static ip's).
We'd also like to have a web interface to plot out the daily traffic of individual pc's sorted by ports ("services"), and the sum traffic per host per day (maybe, per-week also).
Is there any pre-written _free_ software (software groups) that can be used to do this?
All of your help would be appreciated. Thanks!"
(Comments are closed)
By djm () on
You could use Cisco Netflow, most gigabit-capable routers support it, and it is well documented . If you are using an OpenBSD box as a firewall/router (and you don't mind me plugging software I have written), you can use softflowd or pfflowd .
You will still need something to process the traffic records. There are plenty of options here: flow-scan , cflowd , autofocus , or you could just shove all the flows into a SQL database and make your own frontend (it isn't hard).
Comments
By Chad Loder () on
By Matt Van Mater () on
It has rudimentary netflow support, and gives lots of nice traffic summaries that can be sorted by src, dest, protocol, throughput, etc. It has a nice little built in web front end to view all these things.
Comments
By raiten () julien.touche @lycos.com on mailto:julien.touche @lycos.com
but it needs some recent hardware (> 500MHz and a lot of memory depending on your setup)
By Anonymous Coward () on
By free () null@example.org on example.org
else simply setup a bridge, use pf to allow to/fro each ip as an individual rule (with a label) then flex ya inner perl and pass mrtg/rrd some values to plot
By Anonymous Coward () on
By Justin () on
See this screenshot for an example:
http://www.dixongroup.net/hatchet/screen_v06a.jpg
It also has pfstat graphs as well.
Comments
By Thomas () on
Thanks,
Thomas
By Chris Cappuccio () chris@nmedia.net on mailto:chris@nmedia.net
By j0rd () on
Comments
By Anonymous Coward () on
Comments
By michiel () michiel@vanbaak.info on mailto:michiel@vanbaak.info
Comments
By Anonymous Coward () on
Comments
By michiel () michiel@vanbaak.info on mailto:michiel@vanbaak.info
I also followed the apache-mod_proxy howto that is on the ntop homepage. That way you don't have to open direct access to the ntop port. :)
Have fun
By jose () on http://monkey.org/~jose/
http://net.doit.wisc.edu/~plonka/FlowScan/
can pivot on lots of data easily ...
By Steve () on
http://qosient.com/argus/
- Steve
By hubertf () hubertf@hubertf.de on mailto:hubertf@hubertf.de
Screenshots:
http://www.uni-magdeburg.de/steschum/6clt/imgp1740r.jpg
http://www.uni-magdeburg.de/steschum/6clt/imgp1743.jpg
http://www.uni-magdeburg.de/steschum/6clt/imgp1745r.jpg
- Hubert
Comments
By Anonymous Coward () on
By Darian Lanx () spamtrap@uptime.at on mailto:spamtrap@uptime.at
By Jurgen Kobierczynski () on
http://www.caida.org